Privacy policy
What Clavenzo keeps on your devices, what our servers see and keep, who else is involved, and what you can do about it. It describes how the apps and the servers work today. Where something is not built yet, we say so.
In effect from
Who we are
Clavenzo is made and operated by Diamente LLC. In this policy, "we" and "us" mean Diamente LLC.
- Privacy questions and requests: privacy@clavenzo.com
- Security problems: security@clavenzo.com
- Reports of abuse: abuse@clavenzo.com
- Everything else: support@clavenzo.com
The short version
- No phone number. No email. No name. Your identity is a random key your phone or computer makes. There is no account and no password, and your address book is never read.
- What you say and send is encrypted end to end. Calls, video, messages, photos, files, voice messages and shared locations are encrypted on your device, and only the person you send them to can open them. That is true whether they go straight between the two devices or through a relay. We cannot read them.
- Our servers do see some things. They hold your address, your public keys and, for a phone, its push token, and they see which address sends a call invitation or a waiting message to which address. The section below lists all of it, and how long each item is kept.
- No ads, no analytics, no trackers, no crash reports. We do not sell data, and we do not share it for advertising.
What stays on your device
- Your identity's private key. It is made on your phone and stored there. On Android it is sealed with a key held by the Android Keystore, in the phone's secure hardware where the phone has it. On iPhone it is kept in the Keychain, for this device only, and never synced to iCloud. It leaves the phone only if you export it yourself, sealed with a one-time code.
- Your conversations, photos, files, voice messages, call history and contacts. They are kept in the app's private storage, protected by the phone's own encryption and screen lock. The app does not add a second layer of encryption to them. They are left out of Google and iCloud backups. They leave the phone only as encrypted messages to the person you send them to, or in an encrypted backup file you choose to make.
- On a computer, your identity's private key is sealed with a key kept by the system's credential store (Windows Credential Manager, or the Secret Service keyring on Linux), so the file on disk is useless on another account or computer. Your conversations and files are kept in the app's data folder under your user account.
- The names you give your contacts. They stay on your phone and are never sent.
- Your location. Clavenzo never tracks it. When you tap Share my location, one position is sent, encrypted end to end, to that one person.
What our servers see, and how long they keep it
Clavenzo's servers introduce phones to each other, wake a closed app when a call or a message comes in, and hold encrypted items for a phone that is switched off. There are several of them, some on machines of our own and some on machines rented from Google Cloud. Registrations are copied between them, so that any of them can reach you.
This is everything they keep:
| What | What it contains | How long we keep it |
|---|---|---|
| Your registration | Your address (the fingerprint of your identity key), your identity's public key, your platform (Android, iPhone or a computer), your phone's push token (a computer has none), and two public keys signed by your identity (one for key exchange, one post-quantum) that let other devices encrypt to you. | As long as the app keeps checking in. Deleted 30 days after the last check-in. |
| Call invitations | Encrypted. The caller's address and yours. | Until your phone collects it, and never more than 60 seconds. |
| Waiting messages and files | Encrypted. The sender's address and yours, the size and the time it arrived. | Until your phone collects it, and never more than 72 hours. |
| Request logs | The type of each request, its result and how long it took. No IP addresses, no Clavenzo addresses, no push tokens and no content. | Only as long as we need them to fix faults. |
| Relay logs, while we test | For now, each connection through our own relay, with the IP addresses involved, so that we can watch the servers and fix faults. We will turn this off when testing is done, and this policy will say so. | 7 days. |
What this means in practice:
- Who contacts whom. While a call invitation or a waiting message is on our servers, they can see which address sent it to which address. We do not keep a record of these pairs once the item is gone.
- IP addresses. Our servers see the IP address each request comes from while they handle it. They do not write it to the request logs. The relay logs are the one place where we keep IP addresses.
- When you check in. Our servers see when your phone registers and collects, and when it is sent a push.
- Whether an address is registered. Anyone who has your address can ask our servers whether it is registered, whether it is on Android, iPhone or a computer, and for its public keys. That is how another device calls you. It also means that someone who has your address can see whether it is in use.
Our servers never see what you say or send, your contacts, your chat history, or your name, phone number or email address.
Who else is involved
- Cloudflare. Our domain runs through Cloudflare. The encrypted connection from your phone ends at Cloudflare, which passes each request on to our servers through a Cloudflare Tunnel. So Cloudflare can see the same details our servers see: your IP address, which addresses a request is about, the push token in a registration, and the size and time of each request. It cannot see content, which is encrypted end to end before it leaves your phone. Cloudflare also runs relays that carry some calls (see the next section), and it hosts this website.
- Google Cloud. Some of our servers run on machines rented from Google Cloud.
- Apple and Google push services. A closed app can only be woken through Apple Push Notification service on iPhone, or Firebase Cloud Messaging on Android. Firebase Cloud Messaging is the only closed-source third-party code in the Android app. A push carries no sender and no content: it says only whether it is about a call or a message. On iPhone, a message push shows a fixed notification, "New message" and "Tap to read", and a call rings on the iPhone's own call screen, where the app fills in the name you saved for that contact. Apple or Google can see that your phone received a push, of which kind, and when. The desktop apps use no push service: while they run, they collect from our servers themselves.
We do not use any advertising, analytics or crash-reporting company.
Calls: direct or through a relay
- Every call is encrypted end to end, whichever way it travels. A relay forwards bytes it cannot read.
- Calls go direct when they can. To find a direct path, each phone sends the other its network addresses. So the person you call, or who calls you, can learn your IP address, which can show roughly where you are. This happens even when the call ends up going through a relay.
- When the direct path fails, a relay carries the call. The app tries our own relay over UDP, then our own relay over TCP, then Cloudflare's relays, and it moves on to another server when one does not answer. A relay sees the IP addresses of both phones and how much data passes, never what is said.
- There is no setting today that sends every call through a relay.
- The first message of a direct call carries both identity public keys unencrypted, so someone watching that network can tell which two identities are talking, though not what they say.
Post-quantum protection
- Calls. Every call makes fresh keys that are destroyed when it ends. A moment after a call connects, both apps add a post-quantum key exchange (ML-KEM-768), when both apps support it. From then on, a recording of the call is meant to stay unreadable even to a future quantum computer.
- Messages and files. They are sealed with RSA-2048 and ML-KEM-768 together. Today the ML-KEM key is derived from the RSA key, so we do not claim post-quantum protection for messages and files yet.
- Waiting messages have no forward secrecy. Someone who recorded a waiting message and later got hold of your identity's private key could open it.
Your identity, and changing it
- What it is. Your identity is a random RSA-2048 key made on your device. Your address is derived from it, and you share it as a code or a QR code.
- On Android, you get a new identity by clearing Clavenzo's storage in the phone's settings, or by reinstalling the app. For the people you talk to, the new address has no link to the old one. This also deletes your chats on that phone, so make an encrypted backup first if you want to keep them.
- On iPhone, the identity is kept in the Keychain, which iOS keeps when an app is deleted. Reinstalling the app brings back the same identity. See Deleting your data, below.
- What a new identity does not hide. Our servers and Cloudflare still see the same phone: the same push token, until the phone's system issues a new one, and the same IP address. A new identity separates you from your old address for other people. It does not hide from us that the same phone is behind both.
- Moving to a new phone. The identity export seals your key in a file that opens only with a one-time code. It is the only way the key leaves a phone. If you lose your phone without an export, the identity is gone: there is no account to recover it from.
Your local network
- Visible on this Wi-Fi is on by default. It announces your address to devices on the same Wi-Fi network, so that people there see you under Nearby and can call you without adding you first. You can turn it off in Settings.
- Calls on the same Wi-Fi without the internet work in some cases today: on Android, once the phone being called has tapped Ready to receive; on iPhone, only while Clavenzo is open on it; and on a computer, whenever Clavenzo is running. The iPhone may ask for permission to use the local network. Messages and files travel the same way while the app is open on both devices.
Deleting your data
- On Android, uninstalling Clavenzo deletes everything it kept on the phone, including the identity key.
- On iPhone, uninstalling deletes your chats, files and settings, but not the identity key, which stays in the Keychain. Reinstalling picks it up again. After you import an identity, the iPhone also keeps the identity it replaced in the Keychain. Today the only way to remove these keys from an iPhone is to erase the iPhone (Settings, General, Transfer or Reset iPhone, Erase All Content and Settings).
- On a computer, uninstalling Clavenzo leaves your identity and conversations in its data folder, so that reinstalling picks them up again. To delete them, delete that folder (
%APPDATA%\com.clavenzo.desktopon Windows,~/.local/share/com.clavenzo.desktopon Linux) and thecom.clavenzo.desktopentry in the system's credential store. - On our servers, your registration is deleted 30 days after your phone last checked in, and uninstalling the app stops the check-ins. Call invitations are deleted within 60 seconds and waiting messages within 72 hours. Relay logs are deleted after 7 days.
- Asking us. Write to privacy@clavenzo.com with your address, and we will delete your registration from our servers. The app registers again the next time it runs, so uninstall it first if you want the registration gone for good. We may ask you to show that the address is yours.
Your rights
Depending on where you live, laws such as the GDPR give you the right to ask what personal data we hold about you, to have it corrected or deleted, to object to how we use it, and to complain to your data protection authority. We use the information above only to deliver your calls and messages, which is the service you asked for. To use any of these rights, write to privacy@clavenzo.com. We can only find data by your address, because we do not know your name. We answer within 30 days.
Law enforcement
If we receive a valid legal demand, the most we can hand over is what the table above says we hold at that moment. We cannot hand over the content of calls, messages or files, your contacts or your chat history, because we do not have them.
Children
Clavenzo is not for children under 13. Where the law requires an older age to agree to the processing described here (up to 16 in some countries of the European Economic Area), you must be at least that age to use Clavenzo.
Security
To report a security problem, write to security@clavenzo.com. Our security contact details are also published at clavenzo.com/.well-known/security.txt. Clavenzo has not yet had an independent security audit.
Where this design stops
- Your phone is the weak point. Anyone holding your unlocked phone can read your messages. Malware on the phone can read what you type before it is encrypted.
- Timing. The timing of packets during a call can show when someone is speaking, even though what is said stays encrypted.
- Being seen to use Clavenzo. Someone watching your network can tell that you use the app.
- The person you talk to can repeat, record or photograph what you send.
If you need protection from someone who can watch a whole network, understand these limits, use the built-in proxy support, and do not rely on any single tool.
What we are working on
These are not built yet. We will update this policy when they ship.
- Sealed sender, so that our servers and Cloudflare no longer see who contacts whom.
- Post-quantum protection for messages and files, with an ML-KEM key that does not depend on the RSA key.
- Deleting your registration from inside the app, without writing to us.
Changes
When this policy changes, we change the date at the top and publish the new version on this page. The apps show the policy from here.
Contact
Diamente LLC. Write to privacy@clavenzo.com about privacy, security@clavenzo.com about security problems, abuse@clavenzo.com to report abuse, and support@clavenzo.com about anything else.